BPF List
 help / color / mirror / Atom feed
* [PATCH bpf-next v3 0/2] bpf: Fix task work scheduling race
@ 2026-09-22 10:00 Yun Lu
  2026-09-22 10:00 ` [PATCH bpf-next v3 1/2] bpf: Fix task work scheduling and callback race Yun Lu
  2026-09-22 10:00 ` [PATCH bpf-next v3 2/2] selftests/bpf: Add task work scheduling race test Yun Lu
  0 siblings, 2 replies; 6+ messages in thread
From: Yun Lu @ 2026-09-22 10:00 UTC (permalink / raw)
  To: ast, daniel, andrii, eddyz87, memxor, martin.lau, song,
	yonghong.song, jolsa, emil, ihor.solodrai
  Cc: yatsenko, bpf

From: Yun Lu <luyun@kylinos.cn>

This series fixes a race in the bpf_task_work scheduling kfuncs and
adds a regression test for it.

bpf_task_work_irq() publishes a task_work callback before it finishes
using the scheduling round.  A target task running on another CPU can
execute the callback, reset ctx->task and publish STANDBY before the
irq_work handler performs its final state transition.  Concurrent map
value deletion can then make the handler call task_work_cancel() with a
NULL task.  The early STANDBY transition can also let a new round reuse
the context while the old irq_work handler is still running.

Patch 1 captures an independent task reference in the scheduling
handler before task_work_add() and uses it for the post-add
cancellation, so the handler never reads ctx->task after the callback
may have reset it.  A BUSY check in acquire keeps a new round from
starting while a previous handler is still running, which prevents a
delayed handler from consuming the new round's SCHEDULING state.  The
scheduling irq_work is initialized once at context creation.  No
fields or states are added to the context, the callback stays
non-blocking, and the cancellation and destruction paths are unchanged.

Patch 2 adds a 1500-round cross-CPU regression test covering context
reuse, callback completion followed by deletion, and deletion racing
with scheduling.

Changes since v2:

- Kernel: drop irq_work_sync() from the callback and both
  WARN_ON_ONCE() checks, as requested in review.  Following the
  suggested direction, the scheduling handler now takes its own task
  reference around task_work_add() and the post-add cancellation; the
  temporary ctx refcount from v2 is gone as well.  The callback ends
  up unchanged from upstream.
- The BUSY check in acquire is kept: without it a handler delayed
  between task_work_add() and its state cmpxchg can flip the next
  round into a bogus SCHEDULED, which later routes map-value deletion
  into task_work_cancel() with an already-reset ctx->task.
- Selftest is unchanged apart from the rebase.

v2: https://lore.kernel.org/all/20260921101453.69273-1-luyun_611@163.com/

Changes since v1 :

- Kernel: rework the fix per review feedback.  Replace the round_refs
  ownership counter and the extra irq_work objects with a completion
  edge: the callback claims RUNNING and waits for the scheduling
  irq_work via irq_work_sync(), plus one temporary reference from the
  existing ctx refcount and a BUSY check covering the add-failure
  path.  No context fields or states are added.
- Selftest: address review feedback (single packed result store,
  bounded thread-start wait, tolerate the expected deletion-race
  outcomes).

v1: https://lore.kernel.org/bpf/20260918080014.54012-1-luyun_611@163.com/

Testing:

- Built with KASAN, lockdep, PROVE_RCU, DEBUG_ATOMIC_SLEEP and
  KMEMLEAK; test_progs -t task_work and 900 stress rounds in QEMU are
  clean, zero leaks reported.
- Replayed the deterministic reproducer (debug-delay only, not part of
  the series): without the fix it panics reliably in
  task_work_cancel(); with the fix the callback staying non-blocking
  and the guest stays healthy.

Yun Lu (2):
  bpf: Fix task work scheduling and callback race
  selftests/bpf: Add task work scheduling race test

 kernel/bpf/helpers.c                          |  39 ++-
 .../selftests/bpf/prog_tests/test_task_work.c | 283 ++++++++++++++++++
 .../selftests/bpf/progs/task_work_race.c      | 126 ++++++++
 3 files changed, 437 insertions(+), 11 deletions(-)
 create mode 100644 tools/testing/selftests/bpf/progs/task_work_race.c


base-commit: 5dd1818b15d98d4a20806cd00b1b40320b06004f
-- 
2.43.0


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-09-24  9:56 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-22 10:00 [PATCH bpf-next v3 0/2] bpf: Fix task work scheduling race Yun Lu
2026-09-22 10:00 ` [PATCH bpf-next v3 1/2] bpf: Fix task work scheduling and callback race Yun Lu
2026-09-23 17:46   ` Mykyta Yatsenko
2026-09-23 23:04   ` Alexei Starovoitov
2026-09-24  9:55     ` luyun
2026-09-22 10:00 ` [PATCH bpf-next v3 2/2] selftests/bpf: Add task work scheduling race test Yun Lu

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox